Many organisations choose to rename the Built-in Administrator account for the domain for security reasons. Whether or not renaming the account provides any real protection is the matter of some debate. What is clear is that any hacker worth his or her salt is not going to be fooled by the rename, because the account has a well known security identifer:

SID: S-1-5-21domain-500

I was working on something the other day and needed to find the Built-in Administrator account using Powershell. It wasn’t quite as straightforward as I thought it would be. Anyway, here’s what I came up with: